Privacy-Tool Comparison Methodology, Claim Labels, and Corrections

Status: Status: method and common slots resolved from the pinned p4_tools preregistration artifacts and the 140 persisted tool cells (pin commit 373eb3c6, captured 2026-09-30); correction log empty, 0 requests to date. Not legal advice.

Short answer

This hub records the comparison method before any class-specific matrix is read. It is a bounded evidence contract, not a ranked list. The method is pinned to commit 373eb3c6, frozen 140 cells across 12 vendors captured within a single-day window (2026-09-30).

How the comparison methodology works

Method v1 (selection-rules-v1 + attributes-v1, pinned together). tool.method.version Commit slot: 373eb3c62d7b55f5fda4d34c76e7816438fe41dc, pinned 2026-09-30T06:02-04:00. tool.method.commit Capture-boundary slot: 2026-09-30, 10:36–20:09 UTC — a single-day capture window; all 140 cells were captured inside it. tool.method.capture_boundary This hub describes scope, evidence, and correction mechanics without declaring a preferred provider.

How the bounded vendor roster was selected

Roster-listed vendor, product matches one of the three tool classes, primary-source evidence supports the class pair, and any class-specific constraint is recorded as an attribute rather than hidden. tool.method.inclusion_rules Exclusion slot: Excluded when the fact needs hands-on account testing, the source is an affiliate listicle or a review publisher outside the pinned allowlist, the vendor sits outside the frozen 12-vendor roster, or the claim would require a ranking or recommendation. tool.method.exclusion_rules Minimum-class-size slot: 3 distinct eligible vendors per class — every active class clears it today: phone 5, email 6, card 4. tool.method.minimum_class_size Display-order slot: alphabetical_by_operating_entity — an administrative sort by each vendor's recorded legal operating entity, not a ranking. tool.method.display_order

Method fieldFrozen value or artifactVersion or commitCapture boundary
Method versionMethod v1 (selection-rules-v1 + attributes-v1)373eb3c62d7b55f5fda4d34c76e7816438fe41dc2026-09-30
Method commitPinned commit, both preregistration artifacts373eb3c62d7b55f5fda4d34c76e7816438fe41dcpinned 2026-09-30T06:02-04:00
Capture boundary2026-09-30, 10:36–20:09 UTC373eb3c62d7b55f5fda4d34c76e7816438fe41dc2026-09-30
Roster inclusionRoster-listed vendor, matching class, primary-source-supported pair, recorded constraints373eb3c62d7b55f5fda4d34c76e7816438fe41dc2026-09-30
Roster exclusionNo hands-on testing, no affiliate/unlisted-publisher sourcing, no non-roster vendor, no ranking claim373eb3c62d7b55f5fda4d34c76e7816438fe41dc2026-09-30
Minimum class size3 distinct eligible vendors per class (phone 5, email 6, card 4 today)373eb3c62d7b55f5fda4d34c76e7816438fe41dc2026-09-30
Display orderalphabetical_by_operating_entity373eb3c62d7b55f5fda4d34c76e7816438fe41dc2026-09-30
Attribute schema versionpppriv-tool-attributes/v1sha256 173db1cf…095de5caa44cb @ 373eb3c62026-09-30
Attribute definitions8 common + 2 phone-only + 1 email-only + 1 card-only (12 defined attributes)373eb3c62d7b55f5fda4d34c76e7816438fe41dc2026-09-30

Which attributes were preregistered

pppriv-tool-attributes/v1, pinned sha256 173db1cf…095de5caa44cb. tool.method.attribute_schema_version Definition slot: 8 common attributes apply to every class pair (signup_identifiers, later_verification_triggers, retention, deletion, operating_entity, source_availability, audit_report, request_reporting); 2 are phone-only, 1 email-only, 1 card-only. tool.method.attribute_definitions Common attributes and class-specific attributes remain separated by the preregistered schema.

What claim labels and capture dates mean

vendor_stated, public_record, third_party_report, independently_tested — 139 of 140 captured cells are vendor_stated, 1 is third_party_report, 0 are independently_tested. tool.method.claim_labels Source-origin slot: vendor_primary, government_public_record, public_repository, third_party_audit, third_party_review — the 140 cells use vendor_primary (135), public_repository (4), and third_party_audit (1); the other two origins are defined but unused so far. tool.method.source_origins Capture-date slot: Each stated cell carries its own fetch-event timestamp; a capture date records when that source was read, not that it has stayed the same since. tool.method.capture_dates Independent-testing slot: Not permitted in this method version (publish_constraints.independently_tested_allowed_in_v1 is false); 0 of 140 captured cells carry the label, and it is not relabeled as another evidence type. tool.method.independently_tested_availability

Claim labelDefinitionAllowed source originsCapture-date meaning
vendor_statedWhat the provider published on its own primary page or document. 139 of 140 captured cells.vendor_primaryDate the vendor's own page or document was read.
public_recordA qualifying public or government record, or a public source-code repository (used for 4 open-source vendors' source_availability cells).government_public_record, public_repositoryDate the public record or repository was read.
third_party_reportAttributed to an outside source on the pinned review-policy allowlist, or a named third-party audit. 1 of 140 captured cells (addy.io's Securitum security audit).third_party_audit, third_party_reviewDate the outside report or audit was read.
independently_testedEvidence meeting the method's own hands-on testing definition. Not permitted in this method version.(none — disallowed in v1)Not applicable; the field stays empty rather than being filled from another evidence type.

How corrections are requested and logged

One email-based correction procedure, identical for every vendor and every page on the site. tool.method.correction_procedure Correction-log slot: 0 correction requests recorded as of this capture window; the log table renders empty rather than being hidden. tool.method.correction_log

Request dateAffected claimStatusResolution dateChange note
No correction requests recorded as of this capture window.

No affiliate, referral, sponsorship, gift, preferred-access or paid-placement relationship with any listed vendor.

Andrew Pierce's companies sell business-formation, compliance, registered-agent, virtual-office and mail-scanning services. Private Pierce is separate from them and takes nothing from any company it describes.

Submit a correction follows the same procedure for every vendor and every page on this site.

What a masked identifier does not hide

The specified counterparty in the interaction — the merchant on a card transaction, the caller or recipient on a call or text, the recipient on an email — not every participant. tool.common.masked_from Identity-receiver slot: The provider itself, and — per class — a carrier, card-issuing bank partner, or destination-mailbox operator, as each vendor's own operating_entity and retention cells record. tool.common.identity_receivers Lawful-request slot: 0 of the 15 recorded class pairs disclose a lawful-request count; several vendors publish a request-handling process (a response window, a warrant/court-order condition) without a count, and an undisclosed count is recorded as not_disclosed, never inferred as zero. tool.common.lawful_request_transparency Masking one identifier for one counterparty does not erase provider, carrier, issuer, or lawful-request records.

Private phone-number capability

Issues a user-facing telephone number or calling/SMS identity distinct from the user's primary carrier number, scoped to the number_issuance and phone_portability attributes; 5 vendors are eligible today. tool.phone.capability_boundary Phone-specific evidence belongs on Private Phone-Number App Comparison. The hub does not highlight a provider row.

Email-alias capability

Issues alias email addresses or mail-forwarding identities distinct from the user's primary inbox address, scoped to the alias_email attribute; 6 vendors are eligible today. tool.email.capability_boundary Email-specific evidence belongs on Email-Alias Service Comparison. The hub does not highlight a provider row.

Masked-payment capability

Issues virtual, masked, or one-time payment card credentials for merchant transactions, scoped to the payment_card attribute; 4 vendors are eligible today, clearing the frozen minimum of 3, so the class is active, not folded. tool.card.capability_boundary Minimum-class-size slot: 3 distinct eligible vendors per class — every active class clears it today: phone 5, email 6, card 4. tool.method.minimum_class_size Card-specific evidence belongs on Masked-Payment Card Comparison while the class remains active; if folded, this section remains noncomparative and renders no vendor table or vendor links.

Sources

The companion sources.json resolves every method and capability slot from the pinned preregistration artifacts (rigs/content-production/pp-privacy/tools/preregistration/selection-rules-v1.json and rigs/content-production/pp-privacy/tools/preregistration/attributes-v1.json, commit 373eb3c62d7b55f5fda4d34c76e7816438fe41dc) and from the 140 persisted tool cells captured 2026-09-30. Class-specific vendor claims are not repeated here; they belong to the phone, email, and masked-payment comparison pages linked above.

Not legal advice

Tool capabilities, provider policies, and source availability can change. This page describes the comparison method, not operational, legal, financial, or compliance guidance.